Connor Moucka, a 26-year-old from Kitchener, Ontario, pleaded guilty in U.S. District Court for the Western District of Washington to four charges tied to the 2024 Snowflake data breach. The charges include computer fraud, wire fraud, aggravated identity theft, and conspiracy. Between February and October 2024, Moucka and his co-conspirators accessed cloud data from 165 organizations using Snowflake Inc.'s platform, including AT&T, Ticketmaster, and Santander Bank. They stole sensitive information such as names, contact details, payment card data, and banking information.
Moucka developed a program that automated the identification of high-value data and used aliases like judische, catist, and waifu to hide his identity. The group extorted at least $2.5 million in bitcoin from three victims and attempted to sell stolen data for over $6 million on cybercriminal forums. Moucka personally received at least $495,000 in bitcoin. The breach caused more than $9.5 million in losses, including ransom payments and response costs. He was arrested on October 30, 2024, in Kitchener and is scheduled for sentencing on October 27.
John Erin Binns was charged separately in April 2025 in connection with the same scheme. Assistant Attorney General A. Tysen Duva stated the guilty plea sends a message that cybercriminals cannot hide behind anonymity. FBI Cyber Division Assistant Director Brett Leatherman said the case shows hiding behind a screen offers no protection from justice.
Moucka's use of automated tools to target high-value data suggests a shift toward more efficient, scalable cyberattacks by individual hackers. This method increases risk for any organization storing sensitive data on cloud platforms used by thousands. The speed and scale of the breach challenge assumptions about individual hackers being less dangerous than state-backed groups.
Editorial note: AI-assisted opinion. All persons mentioned are presumed innocent until proven guilty. Full disclaimer →